Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 561
CVE-2020-15670
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80.
CVE-2020-15670
Mozilla developers reported memory safety bugs present in Firefox for ...
CVE-2020-15668
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
CVE-2020-15668
A lock was missing when accessing a data structure and importing certi ...
CVE-2020-15667
When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key. This vulnerability affects Firefox < 80.
CVE-2020-15667
When processing a MAR update file, after the signature has been valida ...
CVE-2020-15666
When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
CVE-2020-15666
When trying to load a non-video in an audio/video context the exact st ...
CVE-2020-15665
Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. This could have resulted in an incorrect URL being shown when used in conjunction with other unexpected browser behaviors. This vulnerability affects Firefox < 80.
CVE-2020-15665
Firefox did not reset the address bar after the beforeunload dialog wa ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2020-15670 Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird < 78.2, and Firefox for Android < 80. | CVSS3: 8.8 | 1% Низкий | почти 6 лет назад | |
CVE-2020-15670 Mozilla developers reported memory safety bugs present in Firefox for ... | CVSS3: 8.8 | 1% Низкий | почти 6 лет назад | |
CVE-2020-15668 A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80. | CVSS3: 4.3 | 1% Низкий | почти 6 лет назад | |
CVE-2020-15668 A lock was missing when accessing a data structure and importing certi ... | CVSS3: 4.3 | 1% Низкий | почти 6 лет назад | |
CVE-2020-15667 When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key. This vulnerability affects Firefox < 80. | CVSS3: 8.8 | 2% Низкий | почти 6 лет назад | |
CVE-2020-15667 When processing a MAR update file, after the signature has been valida ... | CVSS3: 8.8 | 2% Низкий | почти 6 лет назад | |
CVE-2020-15666 When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other attacks. This vulnerability affects Firefox < 80 and Firefox for Android < 80. | CVSS3: 6.5 | 1% Низкий | почти 6 лет назад | |
CVE-2020-15666 When trying to load a non-video in an audio/video context the exact st ... | CVSS3: 6.5 | 1% Низкий | почти 6 лет назад | |
CVE-2020-15665 Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. This could have resulted in an incorrect URL being shown when used in conjunction with other unexpected browser behaviors. This vulnerability affects Firefox < 80. | CVSS3: 4.3 | 1% Низкий | почти 6 лет назад | |
CVE-2020-15665 Firefox did not reset the address bar after the beforeunload dialog wa ... | CVSS3: 4.3 | 1% Низкий | почти 6 лет назад |
Уязвимостей на страницу